Helix is a financially motivated data-extortion and ransomware brand linked to the broader UNC6671 cybercriminal cluster and associated with the BlackFile, Redact, Pink, and Falcon names. The brand emerged as part of the fragmentation or rebranding of BlackFile in 2026 and shares infrastructure, phishing templates, victimology, and operational tradecraft with those related extortion brands. Security reporting also notes uncertainty over whether these names represent the same core operators, affiliates, splinter groups, or actors using shared phishing infrastructure, but Helix is consistently tied to the same broader ecosystem. Helix specializes in social-engineering-led intrusions rather than exploitation of software vulnerabilities. Its operators have been observed conducting voice-phishing campaigns in which they impersonate corporate IT help desk personnel, often contacting employees on personal mobile devices and creating urgency around security migrations, passkey enrollment, or multi-factor authentication updates. Victims are directed to adversary-in-the-middle phishing portals that capture credentials and MFA tokens, enabling account compromise, session hijacking, and persistent access to enterprise SaaS and identity environments. Post-compromise activity includes abuse of Microsoft 365 and Okta, password-reset abuse for non-SSO applications, deletion of security notifications and alert emails for defense evasion, and automated large-scale data theft from cloud repositories such as mailboxes, OneDrive, and SharePoint. Helix is primarily an extortion actor. It steals data from victim cloud environments and threatens publication if payment is not made. Its operations include leak-site publication, negotiation pressure, and phased release mechanisms in which stolen data is staged into tiers and unlocked on countdown timers to coerce victims. Publicly reported victim interactions show Helix using negotiation pressure, countdowns, and threatened publication after stalled communications. Reporting ties the broader UNC6671 and BlackFile-linked ecosystem to multimillion-dollar ransom collections in 2026, with demands often in the seven-figure range and negotiated settlements frequently reduced from initial asks. Helix has targeted organizations in transportation, financial services, private equity, legal and professional services, insurance, real estate, healthcare, manufacturing, hospitality, technology, and energy-related sectors. Reported victims and targeting patterns show a strong concentration on U.S.-based enterprises, with additional activity affecting Canadian organizations. The group’s later targeting emphasized high-value organizations likely to hold sensitive corporate, investor, litigation, merger-and-acquisition, and client data that can maximize extortion leverage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against AmSpec.
One of four brands used in BlackFile's split extortion operations sharing infrastructure.
Conducting a ransomware attack against Delek US.
Conducting a ransomware attack against Kennedy Jenks and operating a staged extortion timeline ('T1 is unlocked. T2 in 24 hours, then one day each through T4').
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.